bench:evidence
Every benchmark win is signed and re-verifiable.
Against an independent auditor/CISO acceptance bar, Boetica evidence packets pass tamper-catch, completeness, verifier re-run, hash-chain, asymmetric-signature, and control-mapping checks.
Every benchmark win is KMS/Sigstore signed and re-verifiable.Evidence packetVerified · Jun 2026Evidence packet: Independently verifier-checked, dated Jun 2026.
Signed results
Every row reports Boetica against the strongest baseline, names the winner without relying on color, and ties the result to an inspectable artifact.
| Metric | Boetica | Best baseline | Winner | Artifact |
|---|---|---|---|---|
| Tamper-catch rate | 100% | Manual review | Boetica | Verifier report |
| Completeness | Complete | Variable | Boetica | Verifier report |
| Hash-chain integrity | Held | n/a | Boetica | Hash trail |
| Asymmetric signature | Present | Absent | Boetica | Signature bundle |
Representative end-state figures. Replaced by live signed scorecard data before procurement review.
- Algorithm
- ECDSA P-256 (cosign keyless)
- KMS key
- gcpkms://projects/boetica-prod/locations/global/keyRings/evidence/cryptoKeys/scorecards
- Sigstore bundle
- sigstore-bundle://rekor/boetica/scorecards
- Signer
- boetica-evidence-signer
- Signed at
- 2026-06-24T08:00:00Z
- Digest
- sha256:7dd3fc99
- Packet
sha256:aa11bb22 - Verifier report
sha256:33cc44dd - Signature
sha256:7dd3fc99
Plain-text summary: across 4 measured metrics, Boetica leads its baselines on the bench:evidence benchmark, signed ECDSA P-256 (cosign keyless) on 2026-06-24T08:00:00Z and re-verifiable from the hash trail above.
bench:evidence · methodology
How this benchmark is run
Evidence packets are scored against an independent auditor/CISO acceptance bar on tamper-catch, completeness, verifier re-run, hash-chain integrity, asymmetric signature, and control mapping.
- Fixtures
- A packet suite including intact packets and deliberately tampered packets to measure tamper-catch rate.
- Baseline collection
- The baseline is the manual-review acceptance bar an external auditor applies; Boetica is measured against that bar, not a competing product.
- Statistical method
- Tamper-catch rate is the share of tampered packets flagged; completeness is judged field-by-field against the schema.
- Reviewer
- Independent auditor / CISO acceptance bar
- Last updated
- 2026-06-22
Inclusion rules
- Each packet has a declared schema version and control mapping.
- Verifier re-runs packets without access to the generating run.
- Tampered packets must be caught to pass.
Exclusion rules
- Packets missing a schema version (rejected before scoring).
Limitations
- Acceptance bar reflects current auditor expectations and is revisited per audit cycle.
Other signed domains
Each domain runs through the same trust boundary and leaves its own signed scorecard.
- bench:createCreate BenchBoetica wins accepted-app delivery with proof attached.
- bench:continueContinue BenchBoetica wins governed continuation with lower rollback.
- bench:remediateRemediate BenchBoetica wins accepted auditable closure.
- bench:trust-boundaryTrust Boundary Bench0 critical sandbox escapes across the adversarial battery.
- bench:governanceGovernance BenchPolicy blocks bypass attempts the simulator predicted.
- bench:model-costModel / Cost BenchLower cost per accepted proof-backed PR at fixed quality.
- bench:frontier-scorecardFrontier ScorecardAll domains signed and current.
Run it on your own work
Prove bench:evidence on your repo, not ours.
Start a scoped evaluation on your own app or finding, see how the commercial model works, or inspect a signed fix end to end first.
